malware on laptop

edited November 2009 in Spyware & Virus Removal
Hi, my computer is running slow, so i ran a scan with bitdefender. It said that i had some malware. I've posted my hijack this scan, and my bitdefender scan below.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:52:09 PM, on 03/10/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\16.0.0.125\InstStub.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony Corporation\SmartWi Connection Utility\CCP.exe
C:\Program Files\Sony Corporation\SmartWi Connection Utility\PowerManager.exe
C:\Program Files\Sony Corporation\SmartWi Connection Utility\ThirdPartyAppMgr.exe
C:\Program Files\Sony Corporation\SmartWi Connection Utility\UIManager.exe
C:\Program Files\BitDefender\BitDefender 2009\antispam32\bdimguiaux.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Internet Explorer\IEUser.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - "C:\Program Files\BitDefender\BitDefender 2009\Antispam32\IEToolbar.dll" (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [SmartWiHelper] "C:\Program Files\Sony Corporation\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [VAIOSurvey] "C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BitDefender Arrakis Server (Arrakis3) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate1c9d948b3cbde68) (gupdate1c9d948b3cbde68) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: Intel(R) Sample Collector (SampleCollector) - Intel Corporation - C:\Program Files\Sony\VAIO Care\collsvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

--
End of file - 13122 bytes


Bitdefender scan

BitDefender Log File


Product : BitDefender Total Security 2009
Version : BitDefender UIScanner v.12
Scanning task : New Task
Log date : 03/10/2009 12:08:18 PM
Log path : C:\Users\Baljot\AppData\Roaming\BitDefender\Desktop\Profiles\Logs\user_0001\1254586098_1_02.xml

Scan Paths:

Path 0000: C:\
Path 0001: D:\
Path 0002: E:\
Path 0003: F:\
Path 0004: G:\

Scan Options:

Scan for viruses : Yes
Scan for adware : Yes
Scan for spyware : Yes
Scan for applications : Yes
Scan for dialers : Yes
Scan for rootkits : No

Target Selection Options:

Scan registry keys : Yes
Scan cookies : Yes
Scan boot sectors : Yes
Scan memory processes : Yes
Scan archives : No
Scan runtime packers : Yes
Scan emails : Yes
Scan all files : Yes
Heuristic Scan : Yes
Scanned extensions :
Excluded extensions :

Target Processing:

Default action for infected objects : Disinfect
Default action for suspicious objects : None
Default action for hidden objects : None
Default action for encrypted infected objects : None
Default action for encrypted suspicious objects : None
Default action for password-protected objects : Log as not scanned

Scan engines summary

Number of virus signatures : 4310638
Archive plugins : 44
Email plugins : 6
Scan plugins : 13
System plugins : 5
Unpack plugins : 8

Overall scan summary

Scanned items : 51378
Infected items : 1
Suspicious items : 0
Resolved items : 0
Unresolved items : 1
Password-protected items : 0
Overcompressed items : 0
Individual viruses found : 1
Scanned directories : 22316
Scanned boot sectors : 4
Scanned archives : 20
Input-output errors : 50
Scan time : 00:36:43
Files per second : 22

Scanned processes summary

Scanned : 65
Infected : 0

Scanned registry keys summary

Scanned : 1371
Infected : 0

Scanned cookies summary

Scanned : 26
Infected : 0

Remaining issues:

Object Name Threat Name Final Status [System]=]C:\Program Files\BitDefender\BitDefender 2009\BitDefender InnerFire\midas64-v1_17\plugin_extra.m64 [396] (full dump) Generic.Malware.K!PV.3BF58D62 No action was possible

Comments

  • edited October 2009
    Here's my new hijack this log.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:06:39 PM, on 17/10/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18319)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\Java\jre1.6.0\bin\jusched.exe
    C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
    C:\Program Files (x86)\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\16.0.0.125\InstStub.exe
    C:\Program Files\Sony\VAIO Care\listener.exe
    C:\Program Files\Sony Corporation\SmartWi Connection Utility\CCP.exe
    C:\Program Files (x86)\Windows Media Player\wmplayer.exe
    C:\Program Files\Sony Corporation\SmartWi Connection Utility\PowerManager.exe
    C:\Program Files\Sony Corporation\SmartWi Connection Utility\ThirdPartyAppMgr.exe
    C:\Program Files\Sony Corporation\SmartWi Connection Utility\UIManager.exe
    C:\Program Files\BitDefender\BitDefender 2009\antispam32\bdimguiaux.exe
    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=userinit.exe
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
    O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - "C:\Program Files\BitDefender\BitDefender 2009\Antispam32\IEToolbar.dll" (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [SmartWiHelper] "C:\Program Files\Sony Corporation\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [VAIOSurvey] "C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe"
    O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O13 - Gopher Prefix:
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GR99D3~1.DLL
    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: BitDefender Arrakis Server (Arrakis3) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    O23 - Service: Google Update Service (gupdate1c9d948b3cbde68) (gupdate1c9d948b3cbde68) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    O23 - Service: Intel(R) Sample Collector (SampleCollector) - Intel Corporation - C:\Program Files\Sony\VAIO Care\collsvc.exe
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
    O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
    O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
    O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
    O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
    O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
    O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
    O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
    O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

    --
    End of file - 13238 bytes

    Thanks
  • edited October 2009
    I think you should scan your PC with an anti-malware application too. I recommend Syware Doctor.

    _______________________________
    http://my.opera.com/nesakysiu/blog/
  • edited October 2009
    I ran the scan you told me to. I have posted the results below.

    PC Tools Spyware Doctor
    Date
    Status
    26/10/2009 7:23:55 PM:711
    Service Started
    Spyware Doctor Service Application started 26/10/2009 7:23:55 PM:711
    Anti-Malware Engine
    Anti-Malware engine configuration loaded successfully. 26/10/2009 7:24:11 PM:587
    Scan Started
    Scan Type - Intelli-Scan
    26/10/2009 7:24:14 PM:682
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - apmebf.com/ apmebf.com
    26/10/2009 7:24:14 PM:688
    Infection was detected on this computer
    Threat Name - Adware.Advertising
    Type - Cookie
    Risk Level - Low
    Infection - atdmt.com/ atdmt.com
    26/10/2009 7:24:14 PM:709
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - bellcan.adbureau.net/ bellcan.adbureau.net
    26/10/2009 7:24:15 PM:173
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - insightexpressai.com/ insightexpressai.com
    26/10/2009 7:24:15 PM:332
    Infection was detected on this computer
    Threat Name - Adware.Advertising
    Type - Cookie
    Risk Level - Low
    Infection - mediaplex.com/ mediaplex.com
    26/10/2009 7:24:15 PM:651
    Infection was detected on this computer
    Threat Name - Adware.Advertising
    Type - Cookie
    Risk Level - Low
    Infection - smartadserver.com/ smartadserver.com
    26/10/2009 7:24:16 PM:139
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - advertising.com/ advertising.com
    26/10/2009 7:24:16 PM:144
    Infection was detected on this computer
    Threat Name - Adware.Advertising
    Type - Cookie
    Risk Level - Low
    Infection - atdmt.com/ atdmt.com
    26/10/2009 7:24:16 PM:885
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - sonycanada.112.2o7.net/ sonycanada.112.2o7.net
    26/10/2009 7:24:26 PM:346
    IntelliGuards status
    All IntelliGuards were Enabled 26/10/2009 7:25:07 PM:650
    Immunizer Results
    ActiveX section has been immunized, Processed 10074 items. 26/10/2009 7:33:49 PM:765
    Scan Finished
    Scan Type - Intelli-Scan
    Items Processed - 387983
    Threats Detected - 2
    Infections Detected - 9
    Infections Ignored - 0
    26/10/2009 7:46:06 PM:13
    Smart Update
    Smart Update has determined that Spyware Doctor is up to date 26/10/2009 8:34:41 PM:888
    Power Saving Mode Started
    Power Saving Mode Started 26/10/2009 8:37:14 PM:870
    Power Saving Mode Stopped
    Power Saving Mode Stopped 26/10/2009 10:58:54 PM:139
    Power Saving Mode Started
    Power Saving Mode Started

    Thanks for your help so far,
    Bob39
  • edited October 2009
    OK, remove those infections with Spyware Doctor. Oh and by the way, usually you have to buy Spyware Doctor to remove found infections, but if you do not want that, download a free version from Google Pack website. (don't forger to remove currently installed version of Spyware Doctor).

    Then download CCleaner and delete unnecessary files.
  • edited October 2009
    Sorry for the late reply. I've done the steps that you told me to. Here are the results.

    PC Tools Spyware Doctor
    Date
    Status
    27/10/2009 9:53:11 PM:897
    Service Started
    Spyware Doctor Service Application started 27/10/2009 9:53:11 PM:897
    Anti-Malware Engine
    Anti-Malware engine configuration loaded successfully. 27/10/2009 9:53:42 PM:72
    IntelliGuards status
    All IntelliGuards were Enabled 27/10/2009 9:53:51 PM:742
    Scan Started
    Scan Type - Full Scan
    27/10/2009 9:53:59 PM:41
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - apmebf.com/ apmebf.com
    27/10/2009 9:53:59 PM:69
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - bellcan.adbureau.net/ bellcan.adbureau.net
    27/10/2009 9:53:59 PM:292
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    27/10/2009 9:53:59 PM:479
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - insightexpressai.com/ insightexpressai.com
    27/10/2009 9:54:00 PM:401
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - advertising.com/ advertising.com
    27/10/2009 9:54:00 PM:427
    Immunizer Results
    ActiveX section has been immunized, Processed 10080 items. 27/10/2009 9:54:00 PM:461
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    27/10/2009 9:54:00 PM:958
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - sonycanada.112.2o7.net/ sonycanada.112.2o7.net
    27/10/2009 10:04:11 PM:369
    Smart Update
    Smart update has experienced a download error. Please try again later. 27/10/2009 11:25:54 PM:68
    Scan Finished
    Scan Type - Full Scan
    Items Processed - 217459
    Threats Detected - 1
    Infections Detected - 7
    Infections Ignored - 0
    28/10/2009 12:53:47 AM:477
    Power Saving Mode Started
    Power Saving Mode Started 28/10/2009 5:21:29 PM:538
    Power Saving Mode Stopped
    Power Saving Mode Stopped 28/10/2009 6:00:01 PM:735
    Scheduled task started
    Initializing Scheduled task: Intelli-Scan of this computer 28/10/2009 6:00:02 PM:828
    Scan Started
    Scan Type - Intelli-Scan
    28/10/2009 6:00:09 PM:198
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - apmebf.com/ apmebf.com
    28/10/2009 6:00:09 PM:229
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - bellcan.adbureau.net/ bellcan.adbureau.net
    28/10/2009 6:00:11 PM:223
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    28/10/2009 6:00:11 PM:450
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - insightexpressai.com/ insightexpressai.com
    28/10/2009 6:00:12 PM:456
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - advertising.com/ advertising.com
    28/10/2009 6:00:12 PM:522
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    28/10/2009 6:00:13 PM:237
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - sonycanada.112.2o7.net/ sonycanada.112.2o7.net
    28/10/2009 6:01:13 PM:244
    Scan Finished
    Scan Type - Intelli-Scan
    Items Processed - 4804
    Threats Detected - 1
    Infections Detected - 7
    Infections Ignored - 0
    28/10/2009 7:16:35 PM:502
    Smart Update
    Smart update has experienced a download error. Please try again later. 29/10/2009 3:00:11 AM:764
    Power Saving Mode Started
    Power Saving Mode Started 29/10/2009 3:19:51 AM:211
    Service Stopped
    Spyware Doctor Service Application Stopped 29/10/2009 3:21:32 AM:489
    Service Started
    Spyware Doctor Service Application started 29/10/2009 3:21:32 AM:489
    Anti-Malware Engine
    Anti-Malware engine configuration loaded successfully. 29/10/2009 3:21:32 AM:589
    IntelliGuards status
    All IntelliGuards were Enabled 29/10/2009 3:21:33 AM:369
    Power Saving Mode Started
    Power Saving Mode Started 29/10/2009 3:21:38 AM:169
    Immunizer Results
    ActiveX section has been immunized. No items were processed. 29/10/2009 3:51:41 AM:129
    Smart Update
    Smart update has experienced a download error. Please try again later. 29/10/2009 8:32:49 PM:180
    Power Saving Mode Stopped
    Power Saving Mode Stopped 29/10/2009 10:27:47 PM:755
    Smart Update
    Smart update has experienced a download error. Please try again later. 30/10/2009 1:49:29 AM:260
    Service Stopped
    Spyware Doctor Service Application Stopped 30/10/2009 5:02:16 PM:621
    Service Started
    Spyware Doctor Service Application started 30/10/2009 5:02:16 PM:621
    Anti-Malware Engine
    Anti-Malware engine configuration loaded successfully. 30/10/2009 5:02:17 PM:221
    IntelliGuards status
    All IntelliGuards were Enabled 30/10/2009 5:02:22 PM:795
    Immunizer Results
    ActiveX section has been immunized. No items were processed. 30/10/2009 5:31:09 PM:926
    Smart Update
    Smart update has experienced a download error. Please try again later. 30/10/2009 6:00:09 PM:999
    Scheduled task started
    Initializing Scheduled task: Full scan of this computer 30/10/2009 6:00:10 PM:200
    Scan Started
    Scan Type - Full Scan
    30/10/2009 6:00:14 PM:100
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - apmebf.com/ apmebf.com
    30/10/2009 6:00:14 PM:147
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - bellcan.adbureau.net/ bellcan.adbureau.net
    30/10/2009 6:00:14 PM:459
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    30/10/2009 6:00:14 PM:646
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - insightexpressai.com/ insightexpressai.com
    30/10/2009 6:00:15 PM:761
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - advertising.com/ advertising.com
    30/10/2009 6:00:15 PM:875
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    30/10/2009 6:00:16 PM:511
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - sonycanada.112.2o7.net/ sonycanada.112.2o7.net
    30/10/2009 7:29:00 PM:946
    Scan Finished
    Scan Type - Full Scan
    Items Processed - 223151
    Threats Detected - 1
    Infections Detected - 7
    Infections Ignored - 0
    30/10/2009 11:46:09 PM:263
    Smart Update
    Smart update has experienced a download error. Please try again later. 31/10/2009 12:35:22 AM:625
    Power Saving Mode Started
    Power Saving Mode Started 31/10/2009 11:20:43 AM:284
    Power Saving Mode Stopped
    Power Saving Mode Stopped 31/10/2009 3:50:58 PM:184
    Smart Update
    Smart update has experienced a download error. Please try again later. 31/10/2009 6:00:02 PM:102
    Scheduled task started
    Initializing Scheduled task: Intelli-Scan of this computer 31/10/2009 6:00:02 PM:186
    Scan Started
    Scan Type - Intelli-Scan
    31/10/2009 6:00:05 PM:268
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - apmebf.com/ apmebf.com
    31/10/2009 6:00:05 PM:278
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - bellcan.adbureau.net/ bellcan.adbureau.net
    31/10/2009 6:00:05 PM:479
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    31/10/2009 6:00:05 PM:618
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - insightexpressai.com/ insightexpressai.com
    31/10/2009 6:00:06 PM:429
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - advertising.com/ advertising.com
    31/10/2009 6:00:06 PM:495
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    31/10/2009 6:00:06 PM:967
    Infection was detected on this computer
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - sonycanada.112.2o7.net/ sonycanada.112.2o7.net
    31/10/2009 6:01:16 PM:326
    Scan Finished
    Scan Type - Intelli-Scan
    Items Processed - 5350
    Threats Detected - 1
    Infections Detected - 7
    Infections Ignored - 0
    31/10/2009 8:26:51 PM:890
    Infection cleaned
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - sonycanada.112.2o7.net/ sonycanada.112.2o7.net
    31/10/2009 8:26:52 PM:132
    Infection cleaned
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    31/10/2009 8:26:52 PM:137
    Infection cleaned
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - advertising.com/ advertising.com
    31/10/2009 8:26:52 PM:139
    Infection cleaned
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - insightexpressai.com/ insightexpressai.com
    31/10/2009 8:26:52 PM:145
    Infection cleaned
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - doubleclick.net/ doubleclick.net
    31/10/2009 8:26:52 PM:147
    Infection cleaned
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - bellcan.adbureau.net/ bellcan.adbureau.net
    31/10/2009 8:26:52 PM:148
    Infection cleaned
    Threat Name - Application.TrackingCookies
    Type - Cookie
    Risk Level - Low
    Infection - apmebf.com/ apmebf.com
    31/10/2009 8:26:57 PM:612
    Infections Quarantined/Removed Summary
    Quarantined - 0
    Quarantine Failed - 0
    Removed - 7
    Remove Failed - 0


    Thanks
    Bob39
  • edited November 2009
    Hello Bob, sorry for the late reply.

    A few things before we start....
    1. Please Read All Instructions Carefully.
    2. If you don't understand something, stop and ask! Don't keep going on.
    3. Please do not run any other tools or scans whilst I am helping you.
    4. If you have to go away for an extended period of time, let me know.
    5. Please continue to respond until I give you the "All Clear".
    (Just because you can't see a problem doesn't mean it isn't there)

    =========

    Please download Malwarebytes' Anti-Malware by clicking the link below:
    Malwarebytes Anti-Malware - Reviews and free Malwarebytes Anti-Malware downloads at Download.com

    Double Click mbam-setup.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform Quick Scan", then click Scan.
    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    * Post the contents of the log in your reply.

    Please Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
  • edited November 2009
    Hello, I've ran the scan, and posted the contents below.

    Malwarebytes' Anti-Malware 1.41
    Database version: 3102
    Windows 6.0.6001 Service Pack 1

    04/11/2009 6:42:37 PM
    mbam-log-2009-11-04 (18-42-37).txt

    Scan type: Quick Scan
    Objects scanned: 92395
    Time elapsed: 7 minute(s), 29 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    Thanks
    Bob39
  • edited November 2009
    How is your computer running now? There doesn't seem to be anything bad.
Sign In or Register to comment.